Buyer guide

Ransomware readiness: a checklist

Being ready for ransomware means two things: making an attack harder to pull off, and being able to recover without paying if one succeeds. Most of that comes down to offline backups you have actually restored, strong sign-in controls, prompt patching and a response plan people have rehearsed.

The short answer

You are ready for ransomware when an attacker would struggle to get in, would struggle to spread, and could not stop you recovering. In practice that means:

  • At least two backups kept offline or otherwise out of reach of your network, restored and tested on a schedule.
  • Multi-factor authentication (MFA) on email, remote access, cloud administration and every privileged account.
  • Prompt patching of operating systems, applications and internet-facing devices.
  • Limited administrator rights and a network that is not one flat space.
  • Someone watching for suspicious behavior, including outside business hours.
  • A written response plan with names, phone numbers and decisions agreed in advance.

These points line up with CISA's #StopRansomware resources, which recommend keeping offline, encrypted backups and testing your ability to restore from them regularly.

Start with recovery, because it is your safety net

If everything else fails, your backups decide whether ransomware is a bad week or an existential event. Attackers know this and go after backups early.

What we check first:

  • Is at least one copy offline or immutable? A backup that sits on the same network, with the same administrator password, can be encrypted along with everything else.
  • Are cloud services covered? Microsoft 365, Google Workspace and line-of-business SaaS usually need their own backup; the provider's retention is not the same thing.
  • Have you restored a whole server recently? Restoring one file proves little. Restoring a key system end to end, and timing it, tells you whether your recovery objectives are realistic.
  • Do you know the order of recovery? Identity and network first, then the systems that bring in revenue or keep people safe.

Our article on why a backup is not the same as a recovery plan goes deeper on recovery objectives and testing.

Make getting in harder

Most ransomware incidents start with something ordinary: a stolen password, a phishing email, or an unpatched device facing the internet. CISA's Secure Our World basics and the NIST Cybersecurity Framework cover the same ground.

  • MFA everywhere it matters. Start with email, VPN and remote desktop gateways, cloud admin portals and finance systems. Prefer phishing-resistant methods for administrators.
  • Retire legacy sign-in. Old protocols that cannot do MFA are a common way around it.
  • Patch on a rhythm. Critical updates for internet-facing systems (firewalls, VPNs, remote access tools) cannot wait for the monthly cycle. CISA's Known Exploited Vulnerabilities catalog is a useful guide to what attackers are using right now.
  • Filter email properly and publish SPF, DKIM and DMARC records so your domain is harder to spoof.
  • Remove what you do not use. Old remote access tools, exposed remote desktop and forgotten test servers are frequent entry points.

Make spreading harder

Getting in is only the first step. To cause real damage, an attacker needs administrator access and a path to your servers and backups.

  • Separate admin accounts. Nobody should read email with an account that can change the domain.
  • Least privilege. Staff get the access their role needs, reviewed when they change roles or leave.
  • Segment the network. Keep servers, backups, point-of-sale or production systems and staff devices in separate zones with rules between them.
  • Endpoint detection and response (EDR) on every laptop, desktop and server, so suspicious behavior is spotted before encryption starts. See EDR vs antivirus for what changes.
  • Logging you can actually search, kept long enough to reconstruct what happened.

Rather talk it through? If you are not sure whether your backups would survive an attack, we can review them with you and test a restore. Talk to a Promatics specialist

Decide now what you will do on the worst day

Ransomware decisions are hard to make well at 3 a.m. with systems down. Make them in advance:

  • Who leads? Name an incident lead and a deputy, plus contacts for IT, leadership, legal counsel, communications and your insurer.
  • What gets isolated, and by whom? The first step in most ransomware guidance is to isolate affected systems and disconnect them from the internet and internal networks. Agree who has authority to do that.
  • Who do you call outside? CISA's guidance asks organizations to report ransomware incidents to the FBI, through a local field office or the Internet Crime Complaint Center (IC3), and to CISA. If personal information may be involved, state breach notification laws and sector rules may also apply, and public companies may have SEC disclosure duties; see breach reporting in the US.
  • What is your position on paying? US agencies discourage paying: payment does not ensure you get your data back, and it can carry legal risk, for example if the attacker is subject to US sanctions. Discuss this with leadership, counsel and your insurer before you need to.
  • Where is the plan kept? On paper and somewhere that does not depend on your own systems being up.

Our guide to the first 24 hours of a cyber incident walks through the response itself.

What usually goes wrong

  • Backups that were never restored. The job reported success for months; the data was incomplete.
  • Backups on the domain. Attackers used the same stolen admin account to delete them.
  • MFA with exceptions. A service account or a senior leader was excluded "temporarily" and stayed that way.
  • Alerts nobody saw. The EDR flagged the attack on a Friday evening, and the first person to look was in on Monday.

Ransomware readiness checklist

Recovery

  • Two or more backups, at least one offline or immutable
  • Backup credentials separate from everyday administrator accounts
  • Microsoft 365, Google Workspace and key SaaS data backed up
  • Full restore of a critical system tested and timed in the last six months
  • Recovery order agreed with the business

Prevention

  • MFA on email, remote access, cloud admin and finance systems
  • Legacy sign-in protocols blocked
  • Critical patches for internet-facing systems applied promptly
  • SPF, DKIM and DMARC published for your domains
  • Unused remote access tools and exposed services removed

Containment and detection

  • Separate administrator accounts; least privilege reviewed
  • Network segmented between staff devices, servers and backups
  • EDR on every endpoint and server, with alerts reviewed around the clock
  • Logs retained and searchable

Response

  • Incident lead, deputy and external contacts named
  • Authority to isolate systems agreed
  • Reporting contacts listed (FBI or IC3, CISA, insurer, counsel)
  • Position on ransom payment discussed with leadership
  • Plan printed and stored off your network; tabletop exercise held

When to bring in help

If you have a capable internal IT person, you can work through much of this list yourself, especially MFA, patching and email records. It is worth bringing in a professional when:

  • You cannot say with confidence that a restore would work, or how long it would take.
  • Nobody is watching alerts outside business hours.
  • Your backups, identity and network were set up by different people over many years and nobody has the full picture.
  • An insurer, client or board is asking for evidence, not reassurance.

An AI assistant can give you a good generic checklist. What it cannot do is log in to your backup console, find the service account with no MFA, test a restore on a Saturday and answer the phone when something goes wrong. That is the work our cybersecurity services team does, with 24/7 monitoring and support for managed-service clients.

Limitations

This checklist follows CISA guidance as of its review date. It is general information, not a substitute for an assessment of your own systems, and it is not legal advice about reporting obligations or ransom payments.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. #StopRansomware, Cybersecurity and Infrastructure Security Agency (CISA)
  2. Secure Our World, Cybersecurity and Infrastructure Security Agency (CISA)
  3. Internet Crime Complaint Center (IC3), Federal Bureau of Investigation
  4. NIST Cybersecurity Framework 2.0, National Institute of Standards and Technology

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Find out how ready you really are for ransomware

Ransomware planning can feel overwhelming when you also have a business to run. We will review your backups, sign-in controls and response plan with you and tell you plainly what to fix first.

  • We test whether your backups actually restore, not just run
  • A ranked list of gaps, written for managers as well as IT
  • 24/7 monitoring and support available for managed-service clients